logo

CopyObjection: Fending off ransomware in AWS

ID: 4a967b8f-07a8-5a94-b396-3f33f6857ebb

STIX ID: report--4a967b8f-07a8-5a94-b396-3f33f6857ebb

Feed Name: Red Canary

Date Published: 2025-02-04

Date Updated: 2026-04-29

Author: Jesse Griggs

...
...

This report examines how attackers can leverage AWS S3 server-side encryption with customer-managed keys (SSE-C) to perform copy-in-place ransomware, and evaluates a native AWS detection-and-response pipeline. It details a test setup using CloudTrail and CloudWatch to alarm on rapid CopyObject activity and trigger a Lambda function for automated remediation (disabling access keys or applying deny-all), alongside guidance on preventative configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.